Posts Tagged ‘OECD’
Monday, August 25th, 2014
Many marketing professionals have a common temptation; they want to send as many marketing messages to as many people as possible, and they would love to send it to all folks who have ever been customers or clients of their business, and often times actually want to simply send to everyone whose email address they can obtain in any way.
Privacy professionals make many efforts to guide marketers on what is acceptable and not acceptable. After all, (more…)
Tags:choice, data protection law, FIPs, GAPP, IBM, Information Security, information security risks, infosec, marketing, marketing privacy, midmarket, notice, OECD, PbD, privacy, Privacy by Design, privacy law, privacy principles, privacy professor, privacy risks, privacyprof, Rebecca Herold
Posted in Marketing, privacy | No Comments »
Thursday, July 31st, 2014
What is the difference between security and privacy?
Many of my clients are small and midsized businesses. They often express confusion over what each of these terms (neither of which have a universally-accepted definition) actually means, how they are different, and how they are similar. This is important for business leaders to understand so they can make appropriate decisions within their information security and privacy management programs. Especially in small and midsize businesses, where there may not be a specific position to address either of these important topics. Let’s start with considering at a high level the differences between information security and privacy. (more…)
Tags:data protection law, encryption, FIPs, GAPP, IBM, Information Security, information security risks, infosec, midmarket, OECD, PbD, privacy, Privacy by Design, privacy law, privacy principles, privacy professor, privacy risks, privacyprof, Rebecca Herold
Posted in privacy | No Comments »
Wednesday, February 25th, 2009
Today I spent a lot of time in phone meetings and doing research. So, instead of focusing on writing about one topic today, here are my tweets I sent out, that cover a wide range of topics…
(more…)
Tags:audits, awareness and training, hacker, Information Security, IT compliance, IT training, OECD, policies and procedures, privacy training, risk management, security training
Posted in Information Security, Miscellaneous, Privacy and Compliance | No Comments »
Wednesday, February 25th, 2009
Today I spent a lot of time in phone meetings and doing research. So, instead of focusing on writing about one topic today, here are my tweets I sent out, that cover a wide range of topics…
(more…)
Tags:audits, awareness and training, hacker, Information Security, IT compliance, IT training, OECD, policies and procedures, privacy training, risk management, security training
Posted in Information Security, Miscellaneous, Privacy and Compliance | No Comments »
Sunday, October 28th, 2007
One of the basic privacy principles is to limit the collection of personally identifiable information (PII) to only that which is necessary for the business purpose for which it is being collected. These privacy principles, built largely around the OECD privacy principles, are the basis for most data protection and privacy laws throughout the world.
(more…)
Tags:awareness and training, ID theft, identity theft, Information Security, IT compliance, OECD, PCI DSS, policies and procedures, privacy, privacy principles, privacy training, risk management, security training, SSN
Posted in Information Security, Privacy and Compliance, Training & awareness | No Comments »
Tuesday, August 21st, 2007
Last week my blog poll was, “Is your organization planning to pursue ISO 27001 certification in 2007 or 2008?”
I asked this after reading an SC Magazine article that I recently blogged about, “Are the U.S. Numbers Planning For ISMS (ISO 27001) Certification Really At 80%?”
As I had indicated, based upon my many discussions with a very wide range of CISOs, I thought this number was way too high.
And now for the results of my *ADMITTEDLY UNSCIENTIFIC WEBPOLL*…drum roll, please; Thhuudddrrrrrrrrrrrrr…
(more…)
Tags:awareness and training, Information Security, ISMS, ISO 27001, ISO 27001 certification, ISO27002, IT compliance, OECD, PII, policies and procedures, privacy, risk management
Posted in Information Security | 2 Comments »
Sunday, May 6th, 2007
On May 3 the Organization for Economic and Cooperation and Development (OECD) released a new 24-page guideline,”Principles and Guidelines for Access to Research Data from Public Funding” for organizations in governments throughout the world regarding access to data from publicly funded research projects.
(more…)
Tags:awareness and training, data masking, data protection, government, Information Security, IT compliance, OECD, policies and procedures, privacy, research data
Posted in Information Security, Miscellaneous, Privacy and Compliance | No Comments »
Sunday, May 6th, 2007
On May 3 the Organization for Economic and Cooperation and Development (OECD) released a new 24-page guideline,”Principles and Guidelines for Access to Research Data from Public Funding” for organizations in governments throughout the world regarding access to data from publicly funded research projects.
(more…)
Tags:awareness and training, data masking, data protection, government, Information Security, IT compliance, OECD, policies and procedures, privacy, research data
Posted in Information Security, Miscellaneous, Privacy and Compliance | No Comments »